Improving Protocol Standards for a more Trustworthy Internet
Improving Protocol Standards for a more Trustworthy Internet
批准号:
EP/R04144X/1
负责人:
Colin Perkins
金额:
$29.58万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2018
资助国家:
英国
项目状态:
已结题
起止时间:
2018 至 --
中文摘要
该项目将通过改进网络设计的工程流程,使互联网的基础设施和应用更加可靠和安全,更值得信赖,更不易受到网络攻击。互联网由大量笔记本电脑、智能手机和其他边缘设备组成,通过众多互连链路和交换设备连接到位于世界各地数据中心的服务器。要做到这一点,所有设备必须就它们应该如何通信达成一致。也就是说,它们必须使用一种称为“协议”的共同语言,该“协议”描述了发送的信息的格式和要执行的操作。有许多这样的协议,描述了不同类型的通信。例如,HTTP协议描述了浏览器如何从网站获取页面。为了确保来自不同制造商的设备之间的互操作性,这些协议在一系列标准文档中进行了描述,这些标准文档由互联网工程任务组(IETF)等组织发布。这些标准是由工程师团队在几个月或几年的时间里逐步开发出来的,以产生描述协议应该如何工作的书面规范。尽管制定标准的人尽了最大的努力,然而,结果经常发现包含不一致和含糊不清。由于对标准的不同解释,这些可能导致来自不同制造商的设备无法协同工作,在最坏的情况下,可能导致漏洞,使设备容易受到网络攻击。造成这些不一致和模棱两可的主要原因是协议标准是用英语编写的,因此没有自动检查其正确性的方法。研究人员提出了使用更像计算机编程语言的方法(称为“形式语言”)来描述协议的方法,并且允许进行自动一致性检查,但这些方法尚未被标准社区广泛采用。该项目将研究采用这些新技术的社会、文化和教育障碍,以了解为什么标准继续用英语编写。我们将探讨替代方案的局限性,以理解为什么它们在特定的利基和特定的目的中被采用,但在标准开发中没有更广泛地使用。然后,我们将在协议标准社区中制定一个采用形式语言及其支持工具的模型,并使用它来确定准备在其标准中增加使用此类技术的领域。最后,我们将使用所获得的知识来提出形式语言,这些语言旨在适应标准开发人员的工作方式,并开始将这些语言引入标准过程,以改进协议规范并使其不易受到攻击。这项工作将在IETF中进行,因为它是制定互联网协议标准的关键国际技术标准机构。其目的是提高ietf开发的标准的质量和可信度,并提高互联网的安全性、稳健性和互操作性。我们将探索的新的工程研究思路是,形式语言需要适应社区的兴趣。它们帮助解决如何指定协议的技术问题是不够的:它们必须以一种适合需要使用它们的人的专业知识和文化的方式来做到这一点。对协议设计的结构化方法和形式语言的研究还没有考虑到标准过程的本质,因此没有被广泛采用。我们从对标准过程的深刻认识开始,考虑社会和技术上的障碍,并提出新的技术来改进标准的制定方式。
英文摘要
This project will make the Internet's infrastructure and applications morereliable and secure, more trustworthy and less vulnerable to cyber attack,by improving the engineering processes by which the network is designed.The Internet comprises a large number of laptops, smartphones, and otheredge devices, connecting to servers located in data centres around theworld via numerous interconnecting links and switching devices. To makethis work, all the devices must agree on how they should communicate. Thatis, they must speak a common language, known as a "protocol" that describesthe format of the information that is sent and the operations to beperformed. There are many such protocols, describing the different types of communication. For example, the HTTP protocol describes how browsersfetch pages from websites.To ensure interoperability between devices from different manufacturers,these protocols are described in a series of standards documents, publishedby organisations such as the Internet Engineering Task Force (IETF). Thesestandards are developed incrementally by teams of engineers working overseveral months, or perhaps years, to produce a written specification thatdescribes how the protocol should work. Despite the best efforts of thosedeveloping the standards, however, the results are often found to containinconsistencies and ambiguities. These can lead to devices from differentmanufacturers failing to work together, due to differing interpretations ofthe standard, and in the worst cases can lead to vulnerabilities that opendevices up to cyber attack.Much of the reason for these inconsistencies and ambiguities is that theprotocol standards are written in English, and hence there's no automatedway of checking them for correctness. Researchers have proposed ways ofdescribing protocols using methods (known as "formal languages") that aremore like computer programming languages, and that would allow automatedconsistency checks to be made, but these have not been widely adopted bythe standards community. This project will study the social, cultural, and educational barriers toadoption of these new techniques, to understand why standards continue tobe written in English. We will explore the perceived limitations of thealternatives, to understand why they've been adopted in certain niches, and for certain purposes, but are not used more broadly in standardsdevelopment.We'll then formulate a model for the adoption of formal languages and theirsupporting tools in the protocol standards community, and use it identifyareas that are ready to increase use of such techniques in their standards.Finally, we'll use the knowledge gained to propose formal languages, thatare designed to fit the way the standards developers work, and begin theprocess of introducing these into the standards process, to improveprotocol specifications and make them less vulnerable to attack.The work will be conduced in the IETF, since it's the key internationaltechnical standards body developing Internet protocol standards. The aim isto improve the quality and trustworthiness of the standards that the IETFdevelops, and increase security, robustness, and interoperability of theInternet. The novel engineering research idea we will explore is thatformal languages need to be adapted to the community of interest. It is notenough that they help solve the technical problem of how to specify aprotocol: they must do so in a way that fits the expertise and culture ofthose who need to use them. Research into structured approaches and formallanguages for protocol design has not yet considered the nature of thestandards process, and hence has not seen wide uptake. We start with a deepawareness of the standards process, consider social and technical barriersto uptake, and propose new techniques to improve the way standards aredeveloped.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Investigating Automatic Code Generation for Network Packet Parsing
研究网络数据包解析的自动代码生成
DOI:
10.23919/ifipnetworking52078.2021.9472829
发表时间:
2021
期刊:
影响因子:
--
作者:
[McQuistin S]
通讯作者:
McQuistin S
Parsing Protocol Standards to Parse Standard Protocols
解析协议标准 解析标准协议
DOI:
10.1145/3404868.3406671
发表时间:
2020
期刊:
影响因子:
--
作者:
[McQuistin S]
通讯作者:
McQuistin S
DOI:
10.1145/3284850.3284856
发表时间:
2018-12
期刊:
Proceedings of the Workshop on the Evolution, Performance, and Interoperability of QUIC
影响因子:
--
作者:
[C. Perkins;J. Ott]
通讯作者:
C. Perkins;J. Ott
Considerations around Transport Header Confidentiality, Network Operations, and the Evolution of Internet Transport Protocols
围绕传输标头机密性、网络操作和互联网传输协议演变的考虑
DOI:
10.17487/rfc9065
发表时间:
期刊:
影响因子:
--
作者:
[Fairhurst G]
通讯作者:
Fairhurst G
Streamlining Social Decision Making for Improved Internet Standards
-
批准号:EP/S036075/1
-
项目类别:Research Grant
-
资助金额:$50.99万
-
财政年份:2020
-
负责人:Colin Perkins
-
依托单位:
海外基金